Skip to content

1.4.0 / 2021-08-18

Compare
Choose a tag to compare
@flavorjones flavorjones released this 18 Aug 17:24
2e9ec19

1.4.0 / 2021-08-18

  • Processing Instructions are no longer allowed by Rails::Html::PermitScrubber

    Previously, a PI with a name (or "target") matching an allowed tag name was not scrubbed. There
    are no known security issues associated with these PIs, but similar to comments it's preferred to
    omit these nodes when possible from sanitized output.

    Fixes #115.

    Mike Dalessio